Services Methodology Why Us About Us Blog Get in Touch
← Back to Device Configuration Reviews
// 07D — NETWORK DEVICE HARDENING

Network Device
Review

Configuration hardening review of routers, switches, and firewalls against best security practices including CIS benchmarks and vendor security guides, for Cisco IOS/NX-OS, Palo Alto PAN-OS, Fortinet FortiOS, Juniper JunOS and more...

CIS benchmarksCisco IOS / NX-OSPalo Alto PAN-OSFortinet FortiOSJuniper JunOSACL ReviewFirewall Rulebase ReviewRouting Protocol SecuritySwitch ConfigurationsVPN security
Overview

Network devices sit at the choke points of your infrastructure, but their configurations are often set once at deployment and rarely revisited. Overly permissive firewall rules, weak management-plane authentication, and unauthenticated routing protocols persist for years.

Our network device reviews assess routers, switches, and firewalls against CIS benchmarks and vendor-specific hardening guides for Cisco IOS/NX-OS, Palo Alto PAN-OS, Fortinet FortiOS, and Juniper JunOS — covering management-plane hardening, control-plane protections, and firewall rulebase hygiene.

Rulebases receive manual review alongside automated checks: shadowed rules, unused objects, and "any-any" entries are exactly the kind of thing benchmark scanning alone will miss.

Testing Methodology
01

Scope & Baseline Selection

Confirmation of device models, OS/firmware versions, and role — edge firewall, core switch, VPN gateway — to identify applicable practices and benchmarks.

02

Configuration Extraction

Secure export of running configuration, ACLs, firewall rulebases, and routing tables via SSH, console, or provided configuration backups. No changes made to live devices.

03

Automated benchmark Analysis

Comparison against CIS and vendor benchmarks across management-plane hardening (AAA, SSH, SNMP), control-plane protections, and logging/monitoring configuration.

04

Manual Rulebase & ACL Review

Manual review of firewall rulebases and ACLs for overly permissive "any-any" rules, unused or shadowed rules, weak NAT configuration, and unauthenticated routing protocol peering.

05

Risk Prioritisation

Findings ranked by potential for network segmentation bypass, management-plane compromise, or traffic interception — ordered by exploitability and blast radius.

06

Remediation Guidance & Delivery

Vendor-specific remediation configuration snippets and a prioritised fix list, delivered in a format ready for your change-control process.

What Makes Levantis Different

We review rulebases manually as well as against benchmarks — shadowed and overly permissive rules are the findings that matter most and the ones automated scanning consistently misses.

// In Scope

  • Aruba Networking
  • CheckPoint Firewalls
  • Cisco IOS / IOS-XE / NX-OS devices
  • F5 Networks
  • Fortinet FortiGate
  • Juniper JunOS
  • Palo Alto PAN-OS firewalls
  • Load balancers & VPN concentrators

// Standards

  • CIS benchmarks (vendor-specific)
  • DISA STIGs (Network)
  • NCSC network device guidance
  • Vendor hardening guides

// Typical Duration

  • Up to 2 devices: 3 days
  • 5+ devices: price on request

*Engagement duration dependent on factors such as number of devices, firewall rulebase count, etc

// Engage Us

Ready to scope an engagement? Get in touch for a no-obligation conversation.

Request Assessment

Know your network device hardening gaps.

Firewall and routing configuration set once at deployment rarely gets revisited. Get a clear picture of what's actually enforced at your network edge.

Get in Touch